Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Wild Neutron

Also known as: Jripbot, Morpho, Butterfly, Sphinx Moth

Description

**Toolset/Malware:** Jiripbot, Hesperbot

TTP Summary

Sphinx Moth

AI Analysis

· 1 week ago

Executive Summary

Wild Neutron, an APT group linked to nation-state activities, primarily focuses on espionage through the use of malware such as Jiripbot and Hesperbot. This actor exhibits a high level of technical proficiency, targeting critical sectors in select countries with sophisticated attack vectors. Their operations are characterized by long-term campaigns aimed at data exfiltration and intelligence gathering.

Goals & Targeting

Wild Neutron’s primary motivation appears to be espionage, with a focus on gathering sensitive information from targeted industries. The group selects victims based on their ability to provide valuable intelligence to the nation-state sponsor. Their targeting strategy likely aligns with national security priorities, focusing on sectors such as government, defense, and critical infrastructure.

Enhanced Description

Wild Neutron is a persistent threat group known for its nation-state affiliations and focus on espionage activities. The group operates with a high degree of technical sophistication, employing custom malware like Jiripbot and Hesperbot to compromise targets. These tools are typically used in targeted attacks against government entities, defense organizations, and critical infrastructure sectors. Wild Neutron’s campaigns are characterized by their patient persistence and use of advanced tactics to maintain access and avoid detection. The group's activities suggest a strategic approach to targeting specific sectors and countries, likely aligned with geopolitical interests.

Key Capabilities

  • Custom malware (Jiripbot, Hesperbot)
  • Advanced persistence
  • Spear-phishing campaigns
  • Data exfiltration

MITRE ATT&CK Tactics

Espionage
Intrusion Execution
Collection

ATT&CK Techniques

T1566.001
T1078.001
T1233
T1229

Software / Tooling

Jiripbot
Hesperbot

Campaigns & Victims

Wild Neutron is known for its long-term operational persistence, often maintaining access to compromised networks for extended periods. The group's campaigns are likely tied to specific geopolitical events or intelligence-gathering objectives. Notable past operations include targeted attacks against government and defense sector entities, with a focus on data collection and exfiltration.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Malware-related C2 communication channels
  • Network traffic anomalies indicative of lateral movement

Recommended Actions

  • Implement advanced threat detection solutions for email and network traffic.
  • Conduct regular security audits and monitoring for signs of persistent threats.
  • Educate employees on phishing techniques and suspicious email patterns.

Suggested Tags

APT
espionage
nation-state
government

Confidence Assessment

Low confidence in the exact nature of Wild Neutron's operations due to limited公开 reporting. While the group's toolset and aliases suggest a high level of sophistication, further details on their specific TTPs are unclear. Additional data on campaign patterns and specific victims would improve understanding.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

2

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
espionage
nation-state
government

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.